KA-PRV-001
Privacy Policy
This policy explains how KaWorkout handles personal information across our website, KaWorkout Client, KaWorkout Coach, and related services.
Effective and last updated:
Who is responsible for your information
The data controller is KaWorkout, operated by Anton Kiiko and Kateryna Kiiko.
67 RadbourneDerby
DE22 3HD
United Kingdom
Privacy enquiries: privacy@kaworkout.xyz
What this policy covers
This policy covers personal information handled through:
- kaworkout.xyz and associated KaWorkout marketing pages;
- KaWorkout Client and KaWorkout Coach;
- enquiries, consultations, onboarding and support;
- coaching, programme delivery, fitness, nutrition and wellbeing services;
- payments, transactional communications and notifications; and
- security, monitoring and service diagnostics where those capabilities are used.
The current released Client and Coach application foundations do not provide account creation, coaching-data entry, health-data entry, uploads, notifications or application monitoring. We will review this policy and the relevant consent journey before enabling those capabilities.
Age restriction
KaWorkout is an 18+ service and is not directed at children. People under 18 must not create a KaWorkout Client account, purchase KaWorkout coaching, submit coaching or health information, or use personalised coaching services.
Information we collect
The categories depend on the service you choose to use:
- Contact and enquiry information: name, email address, contact details, and the content of an enquiry, consultation or support request.
- Account, profile and service information: identifiers, authentication details, preferences, programme or service selections, onboarding information and account administration records when these capabilities are made available.
- Coaching and wellbeing information: goals, programme activity, fitness or nutrition information, reflections, coach notes, messages and media that you choose to provide as part of an available service.
- Health information: information you deliberately provide that reveals physical or mental health, injury, medical considerations or similar health status. Not every fitness or wellbeing record is health data; we assess the content and context. Special-category health information is not enabled in a released journey without an explicit-consent mechanism.
- Purchase and payment information: purchase selection, email address, transaction identifiers, payment status, amounts, refunds and accounting records. Stripe collects card or other payment credentials directly; KaWorkout does not need to receive full card details.
- Communications and notification information: messages, support correspondence, delivery status and notification preferences where used.
- Technical and security information: IP address, device and browser type, requested page, timestamps, diagnostic events and security logs generated when you access a released web or application service.
- Marketing preferences: consent, opt-in or opt-out choices where optional direct marketing is offered.
Where information comes from
We usually obtain information directly from you when you visit the site, contact us, begin checkout, make a payment, or use an available KaWorkout service. A coach may create service-administration records from your consultation or coaching interactions. Payment and delivery providers return transaction, status, security and delivery information needed to operate the service.
Why we use information and our lawful bases
| Purpose | UK GDPR lawful basis |
|---|---|
| Responding to requests and delivering purchased or requested services | Article 6(1)(b), contract or steps requested before a contract |
| Account administration, onboarding, consultation, coaching, programme delivery, service communications and connected support | Article 6(1)(b), where genuinely necessary for the service |
| Security, fraud and abuse prevention, service reliability, proportionate diagnostics and protecting KaWorkout systems | Article 6(1)(f), legitimate interests |
| Tax, accounting, regulatory or other legally required processing and retention | Article 6(1)(c), legal obligation |
| Optional direct marketing or another genuinely optional consent-based purpose | Article 6(1)(a), consent |
Our legitimate interests are operating a secure, reliable service, preventing misuse, investigating faults, and protecting users and KaWorkout. We use that basis only where the processing is proportionate and your rights do not override those interests.
Health and other special-category information
Where information supplied for personalised fitness, nutrition or wellbeing coaching constitutes special-category health data, KaWorkout relies on UK GDPR Article 9(2)(a), explicit consent, alongside the appropriate Article 6 lawful basis for the processing purpose.
You may withdraw that consent at any time by using the relevant in-product control when available or emailing privacy@kaworkout.xyz. Withdrawal does not make earlier lawful processing unlawful, but it may mean we cannot continue a personalised service that necessarily depends on that information. We will explain the effect before completing withdrawal.
Who receives information
We share only what is necessary with processors supporting the released service you use. Current and conditional roles include:
- Vercel hosts the website and processes ordinary request, security and deployment information.
- Supabase receives the journey selection and email submitted when checkout is started, and may provide authentication, database and backend processing when those capabilities are released.
- Stripe provides checkout and payment processing when a checkout session is successfully created.
- Resend may process email address, message content and delivery metadata when transactional or application email is enabled.
- OneSignal may process application identifiers, notification preferences, delivery data and limited message content when push notifications are enabled.
- Cloudflare R2 may store user-provided files or media when an approved upload feature is enabled.
- Turso may provide data infrastructure for a released service where specifically enabled.
- Sentry may process minimised diagnostic and error information when monitoring is enabled; health, payment credentials and message content must not be deliberately added to diagnostic metadata.
The present Client and Coach foundations do not activate OneSignal, Cloudflare R2, Turso or Sentry for app-user information. We may also disclose information to professional advisers, regulators, courts, law enforcement, or another party where required by law or necessary to establish, exercise or defend legal rights.
We do not sell personal information.
International transfers
Some service providers may process information outside the United Kingdom, including in the European Economic Area or United States. Where UK data protection law treats a transfer as restricted, we use an applicable UK adequacy regulation or appropriate contractual safeguards, such as the UK International Data Transfer Agreement or UK Addendum, together with supplementary measures where required. You may ask us for more information about the safeguard relevant to your data.
How long we keep information
Our initial retention periods are:
| Information | Retention |
|---|---|
| Unsuccessful enquiries | 12 months after the last interaction |
| Consultations that do not become a client relationship | 12 months |
| Active account and profile information | For the duration of the account or service |
| Coaching records | For the duration of the service, then 3 years |
| Health or other special-category coaching information | For the duration of the service, then 3 years, subject to continuing retention assessment |
| Support correspondence | 24 months after resolution |
| Marketing consent and preferences | Until withdrawal; suppression records may be retained to honour an opt-out |
| Financial, payment and accounting records | Up to 6 years where applicable UK accounting or tax law requires it |
| Routine security and application logs | Normally 90 days, unless reasonably required for security, investigation or legal purposes |
We may keep specific information longer where necessary for a legal claim, security investigation, legal hold, backup cycle or another lawful reason. We minimise access during any extended retention and delete or anonymise the information when the reason ends.
Account and data deletion
You may request account or personal-data deletion through an in-product deletion flow where one is provided, or by emailing privacy@kaworkout.xyz.
We target completion within 30 days, subject to identity verification and information that we must or are legally permitted to retain. Deletion may not be immediate in backups, statutory financial records, security evidence or other records that remain lawfully retained; those records stay protected and are removed or anonymised when the applicable period ends.
Your privacy rights
Depending on the circumstances, you may have the right to:
- be informed about our processing;
- ask for access to your personal information;
- ask us to correct inaccurate or incomplete information;
- ask for erasure or restriction of processing;
- receive eligible information in a portable format;
- object to processing based on legitimate interests or direct marketing;
- withdraw consent at any time; and
- complain to a data protection regulator.
To exercise a right, email privacy@kaworkout.xyz. We may request proportionate information to verify your identity. Rights can have legal exceptions, which we will explain if they apply.
Automated decisions
The current released services do not make solely automated decisions about you that have legal or similarly significant effects. We will update this policy and provide any required safeguards before introducing such processing.
Cookies, devices and diagnostics
The current public site does not use advertising or behavioural tracking and does not set optional analytics cookies. Hosting and security infrastructure processes ordinary request and device information needed to deliver and protect the site. Marketing images are delivered from KaWorkout's website host and do not create a browser request to a separate image provider.
If KaWorkout later introduces optional analytics, advertising, or another non-essential cookie or device identifier, we will update this policy and provide any consent control required before that processing starts.
How we protect information
We apply proportionate technical and organisational measures including access controls, environment separation, encryption in transit, least-privilege provider access, protected secrets, and minimised logs. No internet service can guarantee absolute security; please contact us promptly if you believe your information or account is at risk.
Questions and complaints
Please contact privacy@kaworkout.xyz first so we can investigate. You also have the right to complain to the UK Information Commissioner's Office. Information about making a complaint is available on the ICO website.
Changes to this policy
We review this policy when released services, data uses, providers, retention rules or legal requirements change. We will publish the updated date here and provide additional notice where a change materially affects you.
Return to the KaWorkout homepage.